Senior Application Security Researcher at Kibbi — NeverHard
Senior Application Security Researcher at Kibbi in Toronto, Ontario. Skills: AI, AI Vulnerability Research, Application Security, BigQuery, CI/CD. Apply on NeverHard.
Company
Kibbi
Location
Toronto, Ontario
Type
full_time
Required skills:
AI
AI Vulnerability Research
Application Security
BigQuery
CI/CD
Cloud
Communication
Containers
GO
Kubernetes
The company secures the AI-driven SDLC from prompt to production, unifyingdevelopment and cloud context to stop vulnerabilities at the source. TheSecurity Research group is hiring a senior, hands-on Application SecurityResearcher to push modern AppSec forward — working with engineers, researchersand AI/data scientists on next-generation detection, including autonomous,agentic pen-testing capabilities. This is a build-and-break role, not a typicalAppSec position.
Requirements
5+ years hands-on in offensive security, vulnerability research, orapplication security
Deep understanding of web application and API vulnerabilities, includingbusiness-logic flaws and multi-step attack chains
Strong coding in Python, Go, or similar, with production-quality code shipped
Experience building or tuning detection logic (SAST, DAST, SCA, secrets, orcustom rule engines) and reducing false positives
Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and atleast one major cloud provider
Hands-on use of LLMs / AI models for security tasks, with the judgment tomeasure where they help and where they fail
Comfort with large datasets (SQL, BigQuery, or similar) to drive research andmeasure detection accuracy
Takes research ideas from prototype to production with minimal guidance
Clear written communication — can explain a complex attack path to engineersand product managers
M.Sc. in Computer Science, Cyber Security, or a related field
Nice to have
Published research, CVEs, conference talks, or a bug bounty track record
Experience building AI agents or evaluation frameworks for LLMs
Background in exploit development, red teaming, or penetration testing
Code analysis techniques (taint analysis, call graphs, reachability)
Contributions to open-source security tools
#J-18808-Ljbffr